Source Incite
-
1
Chasing a Dream :: Pre-authenticated Remote Code Execution in Dedecms
-
2
Unlocking the Vault :: Unauthenticated Remote Code Execution against CommVault Command Center
-
3
ZohOwned :: A Critical Authentication Bypass on Zoho ManageEngine Desktop Central
-
4
From Shared Dash to Root Bash :: Pre-Authenticated RCE in VMWare vRealize Operations Manager
-
5
IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit
-
6
Eat What You Kill :: Pre-authenticated Remote Code Execution in VMWare NSX Manager
-
7
JNDI Injection Remote Code Execution via Path Manipulation in MemoryUserDatabaseFactory
-
8
Remote Code Execution with Spring Properties
-
9
Samstung Part 2 :: Remote Code Execution in MagicINFO 9 Server
-
10
Samstung Part 1 :: Remote Code Execution in MagicINFO 9 Server
Staaldraad
-
1
Hipsters and data
-
2
Mongo Shell escape
-
3
Huawei Quidway Password Extraction
-
4
Abusing File Converters
-
5
Viewing, modifying and replaying websockets
-
6
Powershell Shells
-
7
tcpprox - An intercepting TCP proxy
-
8
XXE FTP Server - A {web,ftp}-server for XXE
-
9
NAT-to-NAT VPN with WireGuard
-
10
Phishing with OAuth and o365/Azure
Sucuri Blog
-
1
Vulnerability & Patch Roundup — August 2026
-
2
Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk
-
3
What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk
-
4
The Illusion of a Lock – How AI is changing the speed and scale of hands-on WordPress vulnerability research.
-
5
How to Create a Secure WordPress Staging Site: Beginner’s Guide
-
6
Upgrading How You Sign In to Your Sucuri Account
-
7
Vulnerability & Patch Roundup — July 2026
-
8
Why Delaying WordPress Updates Increases Security Risks
-
9
Vulnerability & Patch Roundup — June 2026
-
10
Joomla SEO Spam Injector: Obfuscated PHP Backdoor Hijacking Site Visitors
The Recurity Lablog
-
1
Safari HSTS Circumvention
-
2
webOS Revisited - Even More Mistaken Identities
-
3
Uwazi.io Security Assessment
-
4
Discover - The good hackers
-
5
Farewell X/Twitter, Hello Bluesky
-
6
Lernraum Berlin - Security Review
-
7
Secure Coding Training
-
8
Recurity Labs Achieves ISO/IEC 27001 Certification – and Shares Lessons Learned
-
9
CVE-2025-54576 - Bypassing Cluster Authentication
-
10
Farewell, Felix
the world. according to koto
-
1
Geocommons.com admin account hijack
-
2
Beatthis! oracle crypto xmas challenge
-
3
Cursorjacking again
-
4
Intro to Chrome addons hacking: fingerprinting
-
5
Chrome addons hacking: want XSS on google.com?
-
6
Chrome addons hacking: Bye Bye AdBlock filters!
-
7
Fun with data: URLs
-
8
CodeIgniter <= 2.1.1 xss_clean() Cross Site Scripting filter bypass
-
9
XSS ChEF - Chrome extension exploitation framework
-
10
How Facebook lacked X-Frame-Options and what I did with it
博客园_知彼知己,百战不殆
-
1
php强制转换类型和CMS远程管理插件的危险 - r00tgrok
-
2
HTML5攻防向量 - r00tgrok
-
3
另类的SQL注入方法 - r00tgrok
-
4
一次部署HTTPS的相关事件引发的思考 - r00tgrok
-
5
你的USB设备还安全吗?USB的安全性已从根本上被打破! - r00tgrok
-
6
对CVE-2014-6271 [破壳漏洞] 的一次不太深入的跟踪 - r00tgrok
-
7
破壳漏洞利用payload—shellshock in the wild - r00tgrok
-
8
Critical: Update Your Windows Secure Channel (cve-2014-6321,MS14-066) - r00tgrok
-
9
When it comes to intrusion analysis and forensics - r00tgrok
-
10
关于信息安全工作方法论的一点猜想 - r00tgrok
Immunity Products
-
1
An Unusual MDaemon Exploit (a.k.a it's not always about shells)
-
2
Jinx Part 2: nginx CVE-2013-2028
-
3
It's SSL Story Time with SILICA
-
4
Therapeutic Ramblings of a Hacker
-
5
Adobe XFA exploits for all! First Part: The Info-leak
-
6
Blackhat 2013 -- A Vendor's Perspective
-
7
Exploiting CVE-2013-3881: A Win32k NULL Page Vulnerability
-
8
Revamping El Jefe
-
9
Connecting El Jefe 2.0 with the Cuckoo malware sandbox
-
10
El Jefe v2.1 Release